PROBABLYPWNED
Home/Tag/Ai Security

Ai Security

50 articles tagged with "Ai Security"

MuddyWater Exploits Langflow Flaw for Initial Access
Vulnerabilities3 min read

MuddyWater Exploits Langflow Flaw for Initial Access

CISA adds CVE-2025-34291 to KEV after Iranian APT MuddyWater weaponizes the CORS/CSRF chain for account takeover and RCE. CVSS 9.4 flaw requires only a malicious link click.

Marcus ChenMay 24, 2026
24 Zero-Days Fall on Day One of Pwn2Own Berlin 2026
Vulnerabilities4 min read

24 Zero-Days Fall on Day One of Pwn2Own Berlin 2026

Security researchers exploited Windows 11, Microsoft Edge, Red Hat Linux, and multiple AI platforms on the first day of Pwn2Own Berlin 2026, earning $523,000 for 24 unique zero-day vulnerabilities.

Marcus ChenMay 14, 2026
One Researcher, Four Critical RCE Bugs in AI Frameworks
Vulnerabilities5 min read

One Researcher, Four Critical RCE Bugs in AI Frameworks

Security researcher Valentin Lobstein discovers CVSS 9.8 pickle deserialization vulnerabilities in LeRobot, ktransformers, and LightLLM. ML frameworks using pickle for network serialization create widespread attack surface.

Marcus ChenApr 26, 2026
LMDeploy SSRF Exploited 12 Hours After Disclosure
Vulnerabilities4 min read

LMDeploy SSRF Exploited 12 Hours After Disclosure

CVE-2026-33626 in LMDeploy AI toolkit was weaponized within 12 hours of publication, targeting AWS credentials and internal services. Patch to v0.12.3 immediately.

Marcus ChenApr 24, 2026
PraisonAI Sandbox Bypass Scores Perfect CVSS 10
Vulnerabilities3 min read

PraisonAI Sandbox Bypass Scores Perfect CVSS 10

CVE-2026-34938 lets attackers escape PraisonAI's three-layer Python sandbox to execute arbitrary OS commands. CVSS 10 — patch to version 1.5.90 immediately.

Marcus ChenApr 4, 2026
LangChain Flaws Expose Files, Secrets, and Databases
Vulnerabilities3 min read

LangChain Flaws Expose Files, Secrets, and Databases

Three vulnerabilities in LangChain and LangGraph expose filesystems, environment secrets, and conversation histories. CVE-2026-34070 enables path traversal. Patches available now.

Marcus ChenMar 28, 2026
Langflow RCE Exploited Within 20 Hours of Disclosure
Vulnerabilities4 min read

Langflow RCE Exploited Within 20 Hours of Disclosure

CVE-2026-33017 (CVSS 9.3) lets attackers execute arbitrary Python code on Langflow AI pipelines without authentication. Exploitation began before any PoC existed.

Marcus ChenMar 21, 2026
Cisco AI Security Report: 83% Want Agents, 29% Ready
Announcements4 min read

Cisco AI Security Report: 83% Want Agents, 29% Ready

Cisco's State of AI Security 2026 report reveals a dangerous gap between agentic AI adoption ambitions and enterprise security readiness. Here's what the threat landscape looks like.

ProbablyPwned TeamFeb 19, 2026
AIUC-1 Becomes First Standard for Securing AI Agents
Announcements4 min read

AIUC-1 Becomes First Standard for Securing AI Agents

Cisco helps build AIUC-1, the first AI agent security standard, mapping its AI Security Framework to testable controls for prompt injection, jailbreaks, and more.

ProbablyPwned TeamFeb 6, 2026
Cisco AI Summit: Security Takes Center Stage
Announcements5 min read

Cisco AI Summit: Security Takes Center Stage

Cisco's second AI Summit unveiled AI Defense, AgenticOps, and Silicon One P200. Here's what security teams need to know about agentic AI governance.

ProbablyPwned TeamFeb 6, 2026
Talos Warns AI Adoption Is Outrunning Security
Announcements5 min read

Talos Warns AI Adoption Is Outrunning Security

Cisco Talos sounds the alarm on AI tools that demand root access and store credentials in plaintext, calling the current adoption frenzy a security crisis.

ProbablyPwned TeamFeb 5, 2026
Cisco Maps the Five Domains of AI Security
Announcements5 min read

Cisco Maps the Five Domains of AI Security

New taxonomy from Cisco's CISO and security leadership defines five AI security domains and the organizational functions needed to secure enterprise AI systems.

ProbablyPwned TeamFeb 4, 2026
OpenSSL Stack Overflow Enables Remote Code Execution
Vulnerabilities5 min read

OpenSSL Stack Overflow Enables Remote Code Execution

CVE-2025-15467 allows attackers to crash or compromise systems by sending malicious CMS messages. All AI-discovered in OpenSSL's largest coordinated security release.

Marcus ChenJan 29, 2026